CVE-2020-1873: High severity Huawei Nip6800 Firmware vulnerability
NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an out-of-bounds read vulnerability. An unauthenticated attacker crafts malformed message with specific parameter and sends the message to the affected products. Due to insufficient validation of message, which may be exploited to cause the device reboot.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NIP6800; Secospace USG6600; USG9500to a version that resolves this vulnerability.Fixed in V500R001C30; V500R001C60SPC500; V500R005C00SPC100Patch out-of-bounds read vulnerability
Event History
Frequently Asked Questions
What is the vulnerability ID for this out-of-bounds read vulnerability?
The vulnerability ID is CVE-2020-1873.
Which Huawei products are affected by this vulnerability?
NIP6800, Secospace USG6600, and USG9500 products with versions of V500R001C30, V500R001C60SPC500, and V500R005C00SPC100 are affected.
What is the severity level of CVE-2020-1873?
The severity level of CVE-2020-1873 is high.
How does an attacker exploit this vulnerability?
An unauthenticated attacker crafts a malformed message with specific parameter and sends it to the affected products.
Is there a fix available for this vulnerability?
Please refer to the vendor's security advisory for instructions on how to mitigate or patch this vulnerability.